{"versionId":"77588fcb-8d4b-4ff9-bb5a-08de96ac93f6","articleId":"558210e3-4169-43f7-e865-08de1b1816db","title":"Connectors and MCP | Admin guide","tags":["connectors","MCP","System admin","All articles"],"content":"<html><head></head><body><p>This guide for administrators explains how to set up Connectors and Model Context Protocol (MCP) in Theta Assist.</p>\n<p>See also:&nbsp;</p>\n<ul>\n<li><a href=\"https://help.thetaassist.ai/article/adding-connectors-to-your-assistant\" target=\"_blank\" rel=\"noopener\">Adding connectors to your assistant</a></li>\n<li><a href=\"https://help.thetaassist.ai/article/connectors-mcp-end-user-guide\" target=\"_blank\" rel=\"noopener\">Guide to connectors for end users</a></li>\n</ul>\n<p>Connectors and&nbsp;MCP enable assistants to interact with external services like Microsoft 365 and Google Workspace as well as custom MCP servers. This can unlock smarter workflows, more meaningful insights and AI actions that are grounded in your business processes and data.</p>\n<p>&nbsp;</p>\n<div class=\"mce-toc\">\n<h2>In this guide...</h2>\n<ul>\n<li><a href=\"#overview\">Overview</a></li>\n<li><a href=\"#supported-connectors\">Supported connectors</a>\n<ul>\n<li><a href=\"#microsoft-365-connectors\">Microsoft 365 Connectors</a></li>\n<li><a href=\"#google-workspace-connectors\">Google Workspace Connectors</a></li>\n<li><a href=\"#other-connectors\">Other Connectors</a></li>\n</ul>\n</li>\n<li><a href=\"#admin-guide\">Admin Guide</a>\n<ul>\n<li><a href=\"#setting-up-oauth-authentication\">Setting Up OAuth Authentication</a></li>\n<li><a href=\"#configuring-connectors\">Configuring Connectors</a></li>\n<li><a href=\"#setting-up-mcp-servers\">Setting Up&nbsp;MCP Servers</a></li>\n<li><a href=\"#microsoft-365-connectors-setup\">Microsoft 365 Connectors Setup</a></li>\n<li><a href=\"#mcetoc_1jjigmhan6u\">Access profiles</a></li>\n<li><a href=\"#mcetoc_1jjih0mbc8q\">MCP logs</a></li>\n</ul>\n</li>\n</ul>\n</div>\n<h2 id=\"overview\">Overview</h2>\n<p>Theta Assist supports two methods for extending assistant capabilities:</p>\n<ol>\n<li><strong>Built-in Connectors</strong>: Pre-configured integrations with popular services that follow the OpenAI Connectors specification - plug and play to get up and running fast</li>\n<li><strong>Model Context Protocol (MCP)</strong>: Industry-standard protocol for connecting assistants to external data sources and tools - for deeper or custom integrations</li>\n</ol>\n<p>Both methods support:&nbsp;</p>\n<ul>\n<li>OAuth 2.0 authentication for secure, delegated access</li>\n<li>Static API key authentication for simpler services</li>\n<li>Granular approval controls for tool execution</li>\n<li>User-level and system-level authentication</li>\n</ul>\n<h2 id=\"supported-connectors\">Supported connectors</h2>\n<p>Theta Assist includes built-in support for the following connectors, documented at <a title=\"OpenAI MCP &amp; Connectors\" href=\"https://developers.openai.com/api/docs/guides/tools-connectors-mcp\" target=\"_blank\" rel=\"noopener\" aria-invalid=\"true\">OpenAI MCP &amp; Connectors</a>. Each connector provides read-only access to data the authenticated user already has permission to access.</p>\n<h3 id=\"microsoft-365-connectors\">Microsoft 365 Connectors</h3>\n<ul>\n<li><strong>Microsoft Teams</strong>: Read Teams, channels, and basic properties</li>\n<li><strong>Outlook Calendar</strong>: Read calendar events and availability</li>\n<li><strong>Outlook Email</strong>: Read inbox messages and email metadata</li>\n<li><strong>SharePoint</strong>: Access OneDrive and SharePoint sites and documents (read-only)</li>\n</ul>\n<h3 id=\"google-workspace-connectors\">Google Workspace Connectors</h3>\n<ul>\n<li><strong>Gmail</strong>: Read Gmail messages and metadata</li>\n<li><strong>Google Calendar</strong>: Read calendar events</li>\n<li><strong>Google Drive</strong>: Access Drive files and folders (read-only)</li>\n</ul>\n<h3 id=\"other-connectors\">Other Connectors</h3>\n<ul>\n<li><strong>Dropbox</strong>: Access Dropbox files and folders (read-only)</li>\n</ul>\n<p>&nbsp;</p>\n<hr>\n<h2 id=\"admin-guide\">Admin Guide</h2>\n<p>Administrators are responsible for:</p>\n<ol>\n<li>Configuring OAuth applications with service providers (Microsoft, Google, Dropbox)</li>\n<li>Enabling connectors and setting approval policies</li>\n<li>Creating global MCP server configurations</li>\n<li>Managing authentication credentials securely</li>\n</ol>\n<h3 id=\"setting-up-oauth-authentication\">Setting Up OAuth Authentication</h3>\n<p>Before connectors can be used, you must configure OAuth authentication for each service provider.</p>\n<h4 id=\"prerequisites\">Prerequisites</h4>\n<ul>\n<li>Administrative access to the service provider (e.g., Azure Entra ID, Google Cloud Console)</li>\n<li>Theta Assist admin permissions</li>\n</ul>\n<h4 id=\"step-1-navigate-to-auth-configurations\">Step 1: Navigate to Auth Configurations</h4>\n<ol>\n<li>Log in to Theta Assist as an administrator</li>\n<li>Navigate to&nbsp;<strong>Admin → Auth Configurations</strong></li>\n<li>Click <strong>+ Add Auth<br></strong></li>\n</ol>\n<p>&nbsp;</p>\n<div><strong><img src=\"https://storage.faqbot.nz/prod/0d5220bc9ad14992d05108dccd460f35/files/pasted_image_article_connectors-and-mcp_3f9b0082-e8af-42e3-b7e0-69f179344297.png\"></strong></div>\n<p>&nbsp;</p>\n<h4 id=\"step-2-configure-oauth-provider\">Step 2: Add OAuth Config</h4>\n<p><strong>Basic Information for a typical setup</strong></p>\n<ul>\n<li><strong>Configuration Name</strong>: Descriptive name (e.g., \"Microsoft 365 Production\")&nbsp;</li>\n<li><strong>Provider</strong>: Select provider (Microsoft, Google, Dropbox, or Other)</li>\n<li><strong>Description</strong> (optional)</li>\n<li><strong>OAuth Server URL:&nbsp;</strong>add the URL of your own OAuth server</li>\n<li>Click <strong>Discover OAuth Endpoints</strong></li>\n</ul>\n<p>Depending on your specific OAuth server setup and the endpoints discovered (or not), follow the relevant guidance below. You may need to provide additional details.</p>\n<p><strong>OAuth 2.0 Settings:</strong></p>\n<p>For&nbsp;<strong>Standard OAuth 2.0</strong> (recommended):&nbsp;</p>\n<ul>\n<li><strong>Authorization URL</strong>: OAuth authorization endpoint&nbsp;</li>\n<li><strong>Token URL</strong>: Token exchange endpoint&nbsp;</li>\n<li><strong>Client ID</strong>: Application/Client ID from provider</li>\n<li><strong>Client Secret</strong>: Application secret (encrypted at rest)&nbsp;</li>\n<li><strong>Scopes</strong>: Space-separated list of OAuth scopes&nbsp;</li>\n<li><strong>Tenant ID</strong>: (Microsoft only) Azure AD tenant ID</li>\n</ul>\n<p>For&nbsp;<strong>Discovery-based OAuth</strong>:</p>\n<ul>\n<li>Enable <strong>Use OAuth Discovery</strong></li>\n<li>Provide <strong>Discovery Endpoint</strong>&nbsp;(e.g.,&nbsp;<code><a href=\"https://login.microsoftonline.com/\">https://login.microsoftonline.com/</a>{tenant}/.well-known/oauth-authorization-server</code>)</li>\n<li>Enable <strong>Use Manual Endpoint Override</strong>&nbsp;to manually specify URLs even with discovery enabled</li>\n</ul>\n<p>For&nbsp;<strong>Dynamic Client Registration</strong> (RFC 7591):</p>\n<ul>\n<li>Enable&nbsp;<strong>Supports Dynamic Registration</strong></li>\n<li>Provide <strong>Registration Endpoint</strong>&nbsp;- System will automatically register and cache client credentials</li>\n</ul>\n<p>For&nbsp;<strong>Static API Key</strong> authentication:</p>\n<ul>\n<li>Leave OAuth fields empty</li>\n<li>Enter <strong>Static Authorization</strong>&nbsp;value (API key) - This bypasses OAuth entirely</li>\n</ul>\n<h4 id=\"step-3-save-configuration\">Step 3: Save Configuration</h4>\n<p>Click&nbsp;<strong>Save</strong>&nbsp;to store the authentication configuration. Secrets are automatically encrypted using AES-256 encryption.</p>\n<p>&nbsp;</p>\n<h3 id=\"configuring-connectors\">Configuring Connectors</h3>\n<p>Once OAuth authentication is configured, enable and configure individual connectors.</p>\n<h4 id=\"step-1-navigate-to-connector-settings\">Step 1: Navigate to Connector Settings</h4>\n<ol>\n<li>Go to&nbsp;<strong>Admin → Tools →Connectors</strong></li>\n<li>View the list of 8 built-in connectors</li>\n</ol>\n<p>&nbsp;</p>\n<div><img src=\"https://storage.faqbot.nz/prod/0d5220bc9ad14992d05108dccd460f35/files/pasted_image_article_connectors-and-mcp_e349c36a-ff7f-42ea-bb76-27d3aa803cca.png\"></div>\n<p>&nbsp;</p>\n<h4 id=\"step-2-configure-each-connector\">Step 2: Configure each connector</h4>\n<p>For each connector you want to enable:</p>\n<ol>\n<li>\n<p><strong>Select Auth Configuration</strong>: Choose the appropriate OAuth configuration (filtered by provider)</p>\n<ul>\n<li>Microsoft connectors require Microsoft auth config</li>\n<li>Google connectors require Google auth config</li>\n<li>Dropbox requires Dropbox auth config<br><br></li>\n</ul>\n</li>\n<li><strong>Add Additional Instructions</strong> (optional): Custom instructions added to the system prompt when this connector is used. These give the AI guidance about how to make best use of the connectors, and improve reliability of results. Microsoft connectors come with default instructions - you can edit these if you wish.<br><br></li>\n<li><strong>Set Approval Policy</strong>:\n<ul>\n<li><strong>Never </strong>require approval: Tools execute automatically (faster, less control)</li>\n<li><strong>Always </strong>require approval: User must approve each tool call (safer, more control)<br><br></li>\n</ul>\n</li>\n<li><strong>Review Available Tools</strong>: View the list of tools and required OAuth scopes for each connector</li>\n</ol>\n<h4 id=\"step-3-save-changes\">Step 3: Save Changes</h4>\n<p>Click&nbsp;<strong>Save Settings</strong>&nbsp;to apply connector configurations. Assistants can now use these connectors.</p>\n<h3>&nbsp;</h3>\n<h3 id=\"setting-up-mcp-servers\">Setting Up&nbsp;MCP Servers</h3>\n<p>MCP servers provide custom integrations beyond built-in connectors. Admins can create global MCP servers available to all assistant authors.</p>\n<h4 id=\"step-1-navigate-to-mcp-settings\">Step 1: Navigate to MCP Settings</h4>\n<ol>\n<li>Go to&nbsp;<strong>Admin → Tools → MCP Servers</strong></li>\n<li>Click&nbsp;<strong>Add MCP Server</strong></li>\n</ol>\n<h4 id=\"step-2-configure-mcp-server\">Step 2: Configure MCP Server</h4>\n<p><strong>Basic Configuration:</strong>&nbsp;</p>\n<ul>\n<li><strong>Server URL</strong>: MCP endpoint URL</li>\n<li><strong>Server Label</strong>: Unique identifier (automatically sanitized, e.g.,&nbsp;<code>my_custom_api</code>)&nbsp;</li>\n<li><strong>Server Name</strong>: Display name for users&nbsp;</li>\n<li><strong>Description </strong>(optional)</li>\n<li><strong>Additional instructions </strong>(optional) - specific guidance to help the AI use this tool effectively</li>\n</ul>\n<p><strong>Authentication (Optional):</strong>&nbsp;</p>\n<ul>\n<li><strong>Auth Configuration</strong>: Select an OAuth config if the MCP server requires authentication - Leave empty for public MCP servers</li>\n</ul>\n<p><strong>Approval Policy:</strong>&nbsp;</p>\n<ul>\n<li><strong>Never </strong>require approval: Tools execute automatically (faster, less control)</li>\n<li><strong>Always </strong>require approval: User must approve each tool call (safer, more control)</li>\n</ul>\n<p><strong>Additional Settings:</strong>&nbsp;</p>\n<ul>\n<li><strong>Allowed Tools</strong>: Optionally restrict which tools from the server can be used (JSON array of tool names)&nbsp;</li>\n</ul>\n<h4 id=\"step-3-save-and-distribute\">Step 3: Save and Distribute</h4>\n<p>Click&nbsp;<strong>Add Server</strong>&nbsp;to create the global MCP server. Assistant authors can now enable it for their assistants.</p>\n<p>&nbsp;</p>\n<h3 id=\"microsoft-365-connectors-setup\">Microsoft 365 Connectors Setup</h3>\n<p>Setting up Microsoft 365 connectors requires creating an Azure Entra ID (formerly Azure AD) App Registration. Below is a detailed change management template you can adapt for your organization.</p>\n<h4 id=\"app-registration-requirements\">App Registration Requirements</h4>\n<p><strong>Configuration Summary:</strong>&nbsp;</p>\n<ul>\n<li><strong>Name</strong>: \"Theta Assist – Connectors (Production)\"&nbsp;</li>\n<li><strong>Type</strong>: Single tenant (Accounts in this organizational directory only)&nbsp;</li>\n<li><strong>Authentication</strong>: Web application with redirect URI(s)&nbsp;</li>\n<li><strong>Permissions</strong>: Delegated, read-only Microsoft Graph permissions&nbsp;</li>\n<li><strong>Client Secret</strong>: Required, store in secure secret management system</li>\n</ul>\n<h4 id=\"required-delegated-permissions\">Required Delegated Permissions</h4>\n<p>Configure the following&nbsp;<strong>Microsoft Graph Delegated</strong>&nbsp;permissions (read-only):</p>\n<p><strong>Authentication &amp; Identity:</strong> &nbsp;</p>\n<ul>\n<li><code>openid</code> - Sign in and read user profile&nbsp;</li>\n<li><code>profile</code> - Read user's basic profile&nbsp;</li>\n<li><code>offline_access</code>&nbsp;- Maintain access to data</li>\n<li><code>User.Read&nbsp;</code>– Read the signed-in user's profile</li>\n<li>&nbsp;</li>\n</ul>\n<p><strong>Outlook Email:</strong>&nbsp;</p>\n<ul>\n<li><code>Mail.Read</code>&nbsp;- Read user mail</li>\n</ul>\n<p><strong>Outlook Calendar:</strong>&nbsp;</p>\n<ul>\n<li><code>Calendars.Read</code>&nbsp;- Read user calendars</li>\n</ul>\n<p><strong>Contacts:</strong></p>\n<ul>\n<li><code>Contacts.Read</code>&nbsp;- Read user contacts (if needed)</li>\n</ul>\n<p><strong>OneDrive &amp; SharePoint:</strong>&nbsp;</p>\n<ul>\n<li><code>Files.Read</code> - Read user files&nbsp;</li>\n<li><code>Sites.Read.All</code>&nbsp;- Read items in all site collections (delegated)</li>\n<li><code>Sites.Read.All</code>&nbsp;– Read items in all site collections (delegated)</li>\n</ul>\n<p><strong>Microsoft Teams:</strong>&nbsp;</p>\n<ul>\n<li><code>Team.ReadBasic.All</code> - Read the names and descriptions of teams&nbsp;</li>\n<li><code>Channel.ReadBasic.All</code>&nbsp;- Read the names and descriptions of channels</li>\n<li><code>Chat.Read</code>&nbsp;– Read user chat messages</li>\n<li><code>ChannelMessage.Read.All</code>&nbsp;– Read all channel messages</li>\n</ul>\n<p><strong>Important</strong>: These are&nbsp;<strong>delegated</strong> permissions, meaning the application can only access data the signed-in user already has permission to access. The app has no elevated privileges.</p>\n<h4 id=\"step-by-step-app-registration-process\">Step-by-Step App Registration Process</h4>\n<p><strong>1. Create App Registration</strong>&nbsp;</p>\n<ol>\n<li>Navigate to&nbsp;<strong>Azure Portal → Microsoft Entra ID → App registrations</strong>&nbsp;</li>\n<li>Click&nbsp;<strong>New registration</strong>&nbsp;</li>\n<li>Enter name: \"Theta Assist – Connectors (Production)\"&nbsp;</li>\n<li>Select <strong>Accounts in this organizational directory only</strong>&nbsp;(Single tenant)</li>\n<li>Add&nbsp;<strong>Redirect URI</strong>: - Type: Web - URI:&nbsp;<code><a href=\"https://your-theta-assist-domain.com/api/mcp-oauth/callback\" aria-invalid=\"true\">https://your-theta-assist-domain.com/api/mcp-oauth/callback</a></code>&nbsp;</li>\n<li>Click&nbsp;<strong>Register</strong></li>\n</ol>\n<p><strong>2. Record Application Details</strong></p>\n<ul>\n<li>Copy <strong>Application (client) ID</strong></li>\n<li>Copy <strong>Directory (tenant) ID</strong></li>\n<li>Save these for Theta Assist configuration</li>\n</ul>\n<p><strong>3. Configure Authentication</strong>&nbsp;</p>\n<p>Navigate to&nbsp;<strong>Authentication</strong> blade</p>\n<p>Under <strong>Platform configurations → Web</strong>:</p>\n<ul>\n<li>Confirm redirect URI</li>\n<li>Set&nbsp;<strong>Front-channel logout URL</strong>&nbsp;(if required)</li>\n</ul>\n<p>Under&nbsp;<strong>Implicit grant and hybrid flows</strong>:</p>\n<ul>\n<li>Ensure <strong>Access tokens</strong>&nbsp;and&nbsp;<strong>ID tokens</strong>&nbsp;are&nbsp;<strong>unchecked</strong> (disabled)</li>\n</ul>\n<p>Under&nbsp;<strong>Advanced settings</strong>:</p>\n<ul>\n<li>Set <strong>Allow public client flows</strong>&nbsp;to&nbsp;<strong>No</strong></li>\n</ul>\n<p>Click&nbsp;<strong>Save</strong></p>\n<p><strong>4. Create Client Secret</strong>&nbsp;</p>\n<ol>\n<li>Navigate to&nbsp;<strong>Certificates &amp; secrets</strong>&nbsp;blade</li>\n<li>Click&nbsp;<strong>New client secret</strong>&nbsp;</li>\n<li>Description: \"ThetaAssist Prod {YYYY-MM-DD}\"</li>\n<li>Expiry: Select per your organization's policy (12 months recommended)&nbsp;</li>\n<li>Click <strong>Add</strong>&nbsp;</li>\n<li><strong>Copy the secret value immediately</strong>&nbsp;(it won't be shown again)</li>\n<li>Store the secret in your approved secret management system (e.g., Azure Key Vault)</li>\n</ol>\n<p><strong>5. Configure API Permissions</strong>&nbsp;</p>\n<ol>\n<li>Navigate to&nbsp;<strong>API permissions</strong>&nbsp;blade</li>\n<li>Click&nbsp;<strong>Add a permission</strong>&nbsp;</li>\n<li>Select&nbsp;<strong>Microsoft Graph</strong>&nbsp;</li>\n<li>Select&nbsp;<strong>Delegated permissions</strong>&nbsp;</li>\n<li>Add the permissions listed above: - openid, profile, offline_access - Mail.Read - Calendars.Read - Contacts.Read - Files.Read - Sites.Read.All - Team.ReadBasic.All - Channel.ReadBasic.All</li>\n<li>Click&nbsp;<strong>Add permissions</strong>&nbsp;</li>\n<li>Click&nbsp;<strong>Grant admin consent for {Your Organization}</strong></li>\n<li>Confirm by clicking <strong>Yes</strong></li>\n</ol>\n<p><strong>6. Configure Theta Assist</strong></p>\n<ul>\n<li>Log in to Theta Assist as administrator</li>\n<li>Navigate to <strong>Admin → Tools → Auth Configurations</strong>&nbsp;</li>\n<li>Click <strong>+Add Auth</strong>&nbsp;</li>\n<li>Fill in:&nbsp;\n<ul>\n<li><strong>Name</strong>: \"Microsoft 365 Production\"&nbsp;</li>\n<li><strong>Provider</strong>: Microsoft&nbsp;</li>\n<li><strong>Tenant ID</strong>: {Your tenant ID from step 2}</li>\n<li><strong>Client ID</strong>: {Your application ID from step 2}</li>\n<li><strong>Client Secret</strong>: {Secret value from step 4}</li>\n<li><strong>Authorization URL</strong>:&nbsp;<code><a href=\"https://login.microsoftonline.com/\">https://login.microsoftonline.com/</a>{tenant-id}/oauth2/v2.0/authorize</code>&nbsp;</li>\n<li><strong>Token URL</strong>:&nbsp;<code><a href=\"https://login.microsoftonline.com/\">https://login.microsoftonline.com/</a>{tenant-id}/oauth2/v2.0/token</code>&nbsp;</li>\n<li><strong>Scopes</strong>:&nbsp;<code>openid profile offline_access Mail.Read Calendars.Read Files.Read Sites.Read.All Team.ReadBasic.All Channel.ReadBasic.All</code></li>\n</ul>\n</li>\n<li>Click&nbsp;<strong>Save</strong></li>\n</ul>\n<p><strong>7. Enable Microsoft Connectors</strong></p>\n<ul>\n<li>Navigate to&nbsp;<strong>Admin → Tools → Connectors</strong></li>\n<li>For each Microsoft connector (Teams, Outlook Calendar, Outlook Email, SharePoint):\n<ul>\n<li>Select the \"Microsoft 365 Production\" auth configuration</li>\n<li>Set approval policy (recommended: \"Always require approval\" for initial rollout)</li>\n<li>Add any additional instructions&nbsp;</li>\n</ul>\n</li>\n<li>Click <strong>Save</strong></li>\n</ul>\n<h3 id=\"mcetoc_1jjigmhan6u\">Access profiles</h3>\n<p>Control who can use specific MCP server(s) by assigning them to access profiles. Add users/groups to the access profile and then assign MCP servers to use the profile. <a href=\"https://help.thetaassist.ai/article/access-profiles-admin-guide\" target=\"_blank\" rel=\"noopener\">Learn more</a>.</p>\n<p>&nbsp;</p>\n<div><img src=\"https://storage.faqbot.nz/prod/0d5220bc9ad14992d05108dccd460f35/files/pasted_image_article_connectors-and-mcp_d85f9f0b-440f-46f9-b5e3-1fddf1a4c04b.png\" width=\"799\" height=\"99\"></div>\n<div>&nbsp;</div>\n<h3 id=\"mcetoc_1jjih0mbc8q\">MCP logs</h3>\n<div>Enable MCP Activity logs if you are looking to debug&nbsp;MCP calls:</div>\n<div>\n<div><img src=\"https://storage.faqbot.nz/prod/0d5220bc9ad14992d05108dccd460f35/files/pasted_image_article_connectors-and-mcp_bb4c8547-86e9-4643-b470-8ca8922935d5.png\" width=\"800\" height=\"125\"></div>\n</div>\n<p>&nbsp;</p>\n<p>&nbsp;</p></body></html>","description":"This guide for administrators explains how to set up Connectors and Model Context Protocol (MCP) in Theta Assist.","isMarkdown":false,"publishedOnUtc":"2026-04-24T06:02:34.5369492","modifiedOnUtc":"2025-11-03T20:32:20.8277262"}